vietnamese Tiếng Việt english English Site-map
Hôm nay:
Tin mới đăng:


Malware Flashback/ Flashfake bùng nổ trên máy Mac của Apple gần đây dường như chỉ là khởi đầu cho một làn sóng tấn công mới nhắm đến hệ thống, theo nhà sáng lập và CEO của hãng bảo mật Kaspersky, Eugene Kaspersky.
Trả lời trang CBR tại Info Security 2012 diễn ra tại Luân Đôn, ông Kaspersky cho rằng Apple sau Microsoft một quãng đường dài khi nói đến bảo mật và sẽ phải thay đổi cách tiếp cận các bản cập nhật theo sau những cuộc tấn công của malware gần đây.
Ông Kaspersky bổ sung thêm rằng công ty ông đang nhìn thấy rất nhiều malware đã nhằm vào các máy Mac. Dòng máy này có sức tiêu thụ rất lớn.Trong quý gần đây, 4 triệu máy Mac đã được bán, tăng 7% so với năm ngoái. Con số này vẫn thấp hơn so với lượng PC bán ra và Kaspersky nói Windows vẫn sẽ là mục tiêu chính của tội phạm mạng.
kaspersky
Eugene Kaspersky, CEO hãng bảo mật Kaspersky
Tuy nhiên ông cũng bổ sung thêm về sự gia tăng malware trên Mac: ”Chỉ là vấn đề về thời gian và thị phần. Tội phạm mạng đã nhận thấy Mac là một khu vực lý thú. Bây giờ chúng ta có nhiều malware hơn chứ không chỉ Flashback và Flashfake. Chào mừng đến với thế giới của Microsoft, hỡi máy Mac. Nó đầy rẫy malware”.
Họ hiểu rằng sẽ rất mau thôi họ cũng sẽ có những vấn đề như Microsoft có cách đây 10 hay 12 năm”, ông Kaspersky nói trong cuộc phỏng vấn. “Họ sẽ phải có những thay đổi đối với chu kỳ cập nhật… và sẽ buộc phải đầu tư nhiều hơn vào các thử nghiệm bảo mật cho phần mềm”.
Đó là những gì Microsoft đã làm trong quá khứ sau khi có quá nhiều vụ việc như Blaster và nhiều loại worm phức tạp đã lây nhiễm trên hàng triệu máy tính trong một thời gian ngắn”, ông bổ sung thêm. “Họ đã phải làm rất nhiều việc để kiểm tra mã tìm lỗi và lỗ hổng. Bây giờ đến lúc Apple phải làm điều tương tự”.
Những khẳng định xuất phát từ Flashback, một biến thể của Mac malware ước tính đã lây nhiểm trên 600.000 máy Mac lúc đỉnh điểm.
Apple đã vá lỗ hổng bị Flashback lợi dụng tấn công, đồng thời hãng cũng phát hành một công cụ gỡ bỏ cho những máy tính nhiễm malware. Nhưng công ty đã nhận được cảnh báo từ các chuyên gia bảo mật vì không vá lỗ hổng sớm hơn. Thậm chí, Apple còn tỏ ra chậm chạp khi mà các công ty bảo mật trong đó có Kaspersky, đã lần lượt cung cấp những công cụ dò và gỡ bỏ malware của riêng họ trước cả khi hãng tung ra bản vá chính thức.
Apple trên thực tế đã củng cố Mac OS X để đối phó với những kẻ tấn công trong vài năm gần đây cũng như phô trương các kế hoạch bổ sung biện pháp bảo vệ trong những phiên bản phần mềm tương lai. Hai phiên bản cuối cùng của Mac OS X có một phần mềm quét malware gọi là Xprotect mà có thể phát hiện và khoanh vùng malware. Công ty cũng sẽ sớm ủy quyền bán những ứng dụng đó trên App Store.
NamNguyen (Theo CNET)

id='post-body-5673862193886367424'>



Windows 8Windows 8, like Windows 7 and Vista before it, is being touted as the most secure version of Windows ever. In past releases, many of the security improvements have come through exploit mitigations such as ASLR and DEP and better software security practices during development. In Windows 8, however, one of the major changes is the addition of UEFI, a BIOS replacement that will include a secure boot sequence to help prevent low-level malware infections. That change, however, is not sitting well with everyone.


The way that Windows 8 client machines will boot is going to be quite different from the way that current Windows PCs do. Instead of a BIOS, Windows 8 PCs will include an implementation of UEFI (Unified Extensible Firmware Interface), which is more flexible and programmable than BIOS is. UEFI will sit between the firmware and the Windows operating system and Microsoft is reportedly going to require that any client machine that runs Windows 8 have a secure boot sequence enabled by default. That sequence will require that whatever software is loaded during boot be signed by one of the keys included in the firmware. If the firmware or software isn't signed by a trusted certificate authority, Windows 8 will not load it.


The impetus for this change in the boot process is that attackers have become proficient in recent years at finding methods to load malware into the BIOS and firmware that underlie the OS. In some cases, rootkits, bootkits and malware that infects the master boot record can not be removed from the machine without re-installing the operating system. Microsoft and security vendors have been trying to find ways defeat these attacks for several years now, and the move to UEFI and secure boot is one of the results of that effort.


It's been a long journey for Microsoft to arrive at this destination. The company has been pushing various versions of a hardware-based security system for nearly a decade now. An early version, originally known as the Windows Next Generation Secure Computing Base and later Palladium, generated quite a bit of controversy when it was first discussed. Many of the elements of the Palladium system are now included as part of some laptops and the Windows 8 UEFI implementation: hardware security modules, secure boot, signing of software, encrypted storage of files. While some portions of what Microsoft has implemented in Windows 8 won't require the use of a TPM (Trusted Platform Module), others will, including support for encrypted hard drives.


These security additions to Windows 8 have some benefits, but there also are some potential drawbacks that worry security and privacy advocates. Ross Anderson of the University of Cambridge worries that there is the potential for hardware-based lock-in included with the Windows 8 changes.


"The extension of Microsoft’s OS monopoly to hardware would be a disaster, with increased lock-in, decreased consumer choice and lack of space to innovate. It is clearly unlawful and must not succeed," Anderson said in a blog post.
There also has been concern in the open-source community that the changes in Windows 8 will prevent users from loading alternate operating systems on Windows-based PCs. There may be some ways for users to circumvent the UEFI implementation and find a method for loading a separate OS, but it would likely be difficult.


"There's no indication that Microsoft will prevent vendors from providing firmware support for disabling this feature and running unsigned code. However, experience indicates that many firmware vendors and OEMs are interested in providing only the minimum of firmware functionality required for their market. It's almost certainly the case that some systems will ship with the option of disabling this. Equally, it's almost certainly the case that some systems won't. It's probably not worth panicking yet. But it is worth being concerned," wrote Matthew Garrett, a developer at Red Hat, in a blog post on the Windows 8 changes.


nb : threatpost

Source: http://dzhenway.blogspot.com/2011/09/secure-boot-in-windows-8-worries.html

id='post-body-7419912513689609071'>


NetworkMiner logo

NetworkMiner


NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc.


without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates from PCAP files.
NetworkMiner collects data (such as forensic evidence) about hosts on the network rather than to collect data regarding the traffic on the network. The main user interface view is host centric (information grouped per host) rather than packet centric (information showed as a list of packets/frames).


NetworkMiner has, since the first release in 2007, become popular tool among incident response teams as well as law enforcement. NetworkMiner is today used by companies and organizations all over the world.











































































NetworkMiner (free edition)NetworkMiner Professional
Live sniffing Yes Yes
Parse PCAP files Yes Yes
Receive Pcap-over-IP Yes
OS Fingerprinting (*) Yes Yes
Port Independent
Protocol Identification (PIPI)
Yes
Export results to CSV / Excel Yes
Configurable file output directory Yes
Geo IP localization (**) Yes
Host coloring support Yes
Command line scripting support Yes (through NetworkMinerCLI)
PCAP parsing speed (***)0.581 MB/s0.457 MB/s (GUI version)
0.735 MB/s (command line version)
PriceFree€ 500 EUR
Download NetworkMiner (free edition) Buy NetworkMiner Professional










 
* Fingerprinting of Operating Systems (OS) is performed by using databases from Satori and p0f
** This product includes GeoLite data created by MaxMind, available from http://maxmind.com/
*** Measured by loading dump.eth0.1059726000 from Defcon 11 (189MB) on a PC with Intel Core 2 Duo (2,66GHz) and 2GB RAM

NetworkMiner can extract files and certificates transferred over the network by parsing a PCAP file or by sniffing traffic directly from the network. This functionality can be used to extract and save media files (such as audio or video files) which are streamed across a network from websites such as YouTube. Supported protocols for file extraction are FTP, TFTP, HTTP and SMB.


NetworkMiner Professional extracted files

 

NetworkMiner Professional showing files extracted from sniffed network traffic to disk

 

NetworkMiner Professional extracted images and pictures

 

NetworkMiner Professional showing thumnails for images extracted to disk

 

User credentials (usernames and passwords) for supported protocols are extracted by NetworkMiner and displayed under the "Credentials" tab. The credentials tab sometimes also show information that can be used to identify a particular person, such as user accounts for popular online services like Gmail or Facebook.


NetworkMiner Professional USB flash drive Another very useful feature is that the user can search sniffed or stored data for keywords.


NetworkMiner allows the user to insert arbitrary string or byte-patterns that shall be searched for with the keyword search functionality.


NetworkMiner Professional comes installed on a specially designed USB flash drive. You can run NetworkMiner directly from the USB flash drive since NetworkMiner is a portable application that doesn't require any istallation. We at Netresec do, however, recommend that you copy NetworkMiner to the local hard drive of your computer in order to achieve maximum performance.


» Buy NetworkMiner Professional «


More Information


For more information about NetworkMiner, please see the NetworkMiner Wiki page on SourceForge.
There are also several blog posts about NetworkMiner on the NETRESEC Network Security Blog:



You can download NetworkMiner v1.1 here:


NetworkMiner_1-1.zip


nb : netresec


Source: http://dzhenway.blogspot.com/2011/09/networkminer-v11-released-windows.html

id='post-body-2795269743329314218'>
Demo: Windows on a Mac 8 Tube. Duration : 6.77 Mins.



Windows 8 Download Here: goo.gl SKB New t-shirt! Get the official SoldierKnowsBest goo.gl Apps: iPhone: Android goo.gl: goo.gl Facebook Fan Page: Google + goo.gl: goo.gl Twitter: twitter.com New Game Channel: youtube.com site: soldierknowsbest. com In this video I show you how to get from Microsoft Windows to 8 and a demonstration of how it works on a Mac


Keywords: windows8, mac, howto, os, software, microsoft, vmware fusion, 4 computer, tutorial, metro ui, demo, apple, imac desktop

Source: http://saleforsoftware.blogspot.com/2011/09/demo-windows-on-mac-8.html

Quản Trị Mạng - Hôm qua, Microsoft đã cung cấp 13 cập nhật bảo mật giúp vá 22 lỗi trong Internet Explorer, Windows, Office và phần mềm khác, bao gồm một lỗi đã xuất hiện từ 2 thập kỷ trước, có tên "Ping of Death".
Trong số 13 bản cập nhật, được Microsoft gọi là "bulletins", 2 bản được gắn nhãn “nghiêm trọng” - mức cao nhất của công ty này – 9 bản được đánh giá “quan trọng”, mức nguy hiểm thứ 2 và 2 bản còn lại được xếp hạng “trung bình”.
Bản cập nhật tháng 8 của Microsoft
Có 22 lỗ hổng đơn được vá lần này trong số 13 bulletins được đánh giá là nghiêm trọng. Số còn lại, lần lượt là 15 và 4 lỗ hổng, nằm trong nhóm quan trọng và trung bình.
Các nhà nghiên cứu gọi MS11-057, giúp vá 7 lỗi trong Internet Explorer (IE), là quan trọng nhất và cần được vá ngay lập tức.
Đây là cập nhật dành riêng cho IE, đúng như những gì chúng ta đã mong đợi. Điều quan trọng nhất là nó ảnh hưởng tới IE9”. Andrew Storms, Giám đốc điều hành bảo mật tại nCircle Security, đã nói khi ám chỉ thói quen cập nhật cho trình duyệt 2 tháng một lần của Microsoft.
Bản vá cho IE lần này là bản thứ 2 Microsoft cung cấp để vá các lỗ hổng nghiêm trọng của IE9 trên Vista và Windows 7. Microsoft đã vá lỗ hổng đầu tiên của IE9 vào tháng 6.
"MS11-057 áp dụng cho tất cả các phiên bản của Windows và tất cả những gì nó cần là các trang web có chứa mã độc để chiếm quyền quản lý máy tính. Không còn nghi ngờ gì cả, bản vá này xứng đáng đứng ở vị trí hàng đầu trong danh sách”, Wolfgang Kandek, giám đốc công nghệ của hãng bảo mật Qualys đã nói.
Các chuyên gia bảo mật khác đến từ Symantec và Kaspersky Lab cũng đề cao bản cập nhật cho IE như một bản mà người dùng nên triển khai đầu tiên.
Joshua Talbot, giám đốc bộ phận an ninh của Symantec Security Response, đã nói: “Cả 2 (lỗ hổng nghiêm trọng) có thể bị khai thác bởi một download drive-by. Sự thật là các lỗ hổng như vậy đang ngày càng trở nên phổ biến và đó chính là lý do tại sao tấn công trên web đang rất thịnh hành”.
Tấn công download drive-by là kiểu được thực hiện đơn giản bằng cách điều hướng một trình duyệt lỗi tới một trang web chứa mã độc. Người dùng thường bị lừa truy cập vào các trang web khi thực hiện tìm kiếm hoặc các đường link có trong email message spam.
Hầu hết các chuyên gia, bao gồm cả những người đang làm việc cho Microsoft, cho rằng MS11-058 là bản cập nhật thứ 2 cần được áp dụng càng sớm càng tốt.
Nó sẽ giúp vá 2 lỗ hổng nghiêm trọng trong dịch vụ DNS (domain name system) của Microsoft, được sử dụng bởi rất nhiều doanh nghiệp để dịch các địa chỉ Internet sang các miền mọi người có thể nhận dạng được.
Microsoft xếp hạng một lỗ hổng của MS11-058 là nghiêm trọng trên Windows Server 2008 và Server 2008 R2 khi chạy dịch vụ DNS. Họ cũng cảnh báo rằng hacker có thể khai thác từ xa các dịch vụ này rất đơn giản bằng cách gửi một truy vấn.
Theo Microsoft, lỗ hổng này có thể giúp hacker, kẻ đã thành công trong việc khai thác lỗ hổng này, chạy mã bất kì trên server DNS Windows Server 2008 và Windows Server 2008 R2 có cấu hình DNS.
Marcus Carey, chuyên gia nghiên cứu của Rapid7 đã nói: “Điều này rất quan trọng bởi rất nhiều doanh nghiệp và tổ chức đang sử dụng sản phẩm của Microsoft đều kích hoạt DNS trên server của họ”.




Lamle (Theo Computerworld)

id='post-body-2708047358295467002'>
The error reporting feature is what produces those alerts after certain program or operating system errors, prompting you to send the information about the problem to Microsoft.


You might want to disable error reporting to avoid sending private information about your computer to Microsoft, because you're not connected to the Internet all the time, or just to stop being prompted by the annoying alerts.


Error reporting in enabled by default in all versions of Windows but is easy to turn off.
Answer: You can disable error reporting from the Control Panel in Windows.


The specific steps involved in disabling error reporting depends significantly on which operating system you're using:


    * How To Disable Error Reporting in Windows 7


    * How To Disable Error Reporting in Windows Vista


    * How To Disable Error Reporting in Windows XP


Note: Error reporting in Windows is beneficial for Microsoft but it's also ultimately a good thing for you, the Windows owner. These error reports send vital information to Microsoft about a problem that the operating system or a program is having and helps them develop future patches and service packs, making Windows more stable.

Source: http://softwarewithtools.blogspot.com/2011/07/how-do-i-disable-error-reporting-in.html

id='post-body-3996209250051385622'>
It's a common human desire to maintain up with the Joneses and even to play games of oneupmanship, and it's no truer when applied to PCs. while older package and software may perhaps do the job admirably, there's no ignoring the desire for new shiny toys and the newest in cutting-edge technology.
Windows 8 isn't out yet -- the very first beta isn't due to appear for another few months yet -- but that doesn't end people from wanting it. windows 8 UX Pack 2.0 gives you the next best thing: it tends to make windows 7 look and feel just like windows 8.
You'll need to be operating windows 7 to get satisfaction from this preview -- XP and Vista users will be sadly disappointed as it's not compatible with older adaptations of the OS. when you've downloaded windows 8 UX Pack 2.0, unzip the program installer and double-click it to start the setup process. You'll be asked what windows 8 theme you want to apply, which includes the logon screen wallpaper and the desktop wallpaper.
You can also opt to enable or disable three main windows 8 features here, which includes the Taskbar user Tile (which sits in the bottom most suitable of the Taskbar, forcing the Notification place to sidle more than to the left slightly), the Metro user interface and Aero auto-colorization feature.
Once you've set the options which you want, click "Install" and watch your system transform. You'll find the Taskbar user Tile sits somewhat uncomfortably to the most suitable of the Taskbar's Notification area, forcing it throughout slightly to the left. The Metro user interface gives you an idea of how windows 8 will adopt a radically distinctive approach to using the desktop, taking particular benefit of touchscreens. on this preview a few fundamental tools, which includes Gmail, are accessible.
Once the novelty of the windows 8 UI wears off, getting back to excellent old windows 7 is fairly easy, too. Just operate the program again and instead of choosing "Install", select "Uninstall" as well as your system should be back to in which it experienced been when you started.
As with making any tweak that involves altering system files, it's a good idea to make sure you have a total backup before you apply it. you could use windows 7's own drive-imaging tool, accessible via the Backup and Restore tool, or go for a a whole lot more fully functional third-party app like Paragon's Backup and Recovery 2011 (Advanced) Free, our current preferred no-cost drive-imaging tool. That way you have anything to fall back on should disaster strike, which didn't come about on possibly of the two test products we ran windows 8 UX Pack 2.0 on.
Windows 8 UX Pack 2.0 is available as a freeware obtain now for PCs operating windows 7 (32- or 64-bit).

Source: http://softwarewithtools.blogspot.com/2011/07/you-dont-have-to-wait-for-windows-8.html

Phần mềm độc hại (malware) mới, ẩn trong Master Boot Record (MBR) của máy tính, làm vô hiệu quá các nỗ lực làm sạch máy tính.
Microsoft khuyến cáo người dùng Windows rằng, họ sẽ phải cài đặt lại hệ điều hành (HĐH) nếu máy bị nhiễm loại rootkit mới ẩn trong phần mồi khởi động (boot sector) của máy.

Một biến thể mới của trojan mà Microsoft gọi là "Popureb" đào rất sâu vào hệ thống. Cách duy nhất để tiêu diệt Popureb là đưa Windows trở về cấu hình như lúc mới mua, kỹ sư Chun Feng của nhóm bảo mật Microsoft Malware Protection Center (MMPC) cho biết.

"Nếu hệ thống của bạn bị nhiễm trojan Win32/Popureb.E, chúng tôi khuyên bạn sửa MBR và sau đó sử dụng đĩa CD phục hồi (recovery CD) để khôi phục hệ thống của bạn về trạng thái trước khi bị nhiễm bệnh", ông Feng nói. Đĩa phục hồi đưa Windows trở lại những thiết lập tại nhà máy của nó.

Các malware như Popureb ghi đè lên MBR của ổ đĩa cứng. MBR là sector đầu tiên - Cylinder 0, Head 0, Sector 1 - gồm 512 byte chứa đoạn mã tự mồi (bootstrap) HĐH sau khi BIOS kết thúc quá trình kiểm tra khi máy mới bật. Do Popureb ẩn trên MBR, rootkit trở nên thực sự vô hình với cả HĐH và phần mềm bảo mật.

Theo ông Feng, Popureb phát hiện các hoạt động ghi nhằm vào MBR - những hoạt động được thiết kế để “cọ sạch” MBR và nhiều sector đĩa khác có chứa mã tấn công - và sau đó hoán đổi hoạt động ghi thành hoạt động đọc.

Vì thế, mặc dù hoạt động ghi có vẻ như thành công, nhưng dữ liệu mới không thực sự được ghi vào đĩa. Nói cách khác, quá trình làm sạch sẽ thất bại.

Ông Feng đã cung cấp các liên kết đến những hướng dẫn khắc phục MBR cho XP, Vista và Windows 7.Từ khóa: cài lại Windows, Microsoft, windows
Nguồn: Computerworld, 27/6/2011